Duqu First Spotted as ‘Stars’ Malware in Iran
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2011-3402 | Remote Code Execution in Microsoft Windows Kernel TrueType Font Parser (win32k.sys) CVE-2011-3402 is a flaw in the TrueType font parsing engine of win32k.sys, part of the kernel-mode drivers in Microsoft Windows. A remote attacker can trigger it by presenting crafted font data to a user — for example, embedded in a Word document or on a web page — and gains the ability to execute arbitrary code on the target system. All Microsoft Windows versions covered by the vendor advisory are affected; the provided data does not enumerate specific version ranges. The vulnerability was famously exploited in the wild in 2011 by the Duqu malware campaign (the subject of Microsoft Security Advisory 2639658), and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06. EPSS assigns a 78.3% probability of exploitation within the next 30 days; no current public proof-of-concept is known. Do: Verify that every Windows host — prioritizing legacy, embedded, and internet-exposed machines — has the TrueType font-parsing fix released via Microsoft Security Advisory 2639658 (November 2011), and inventory missing patches rather than assuming modern builds are covered. Per CISA KEV/BOD 22-01 guidance, apply vendor mitigations or discontinue use of the product where patching is not possible. Given the 2025-10-06 KEV listing and 78.3% EPSS, treat any host without the win32k.sys font-parsing update as exposed and remediate within required timelines. | — | 78% | KEV |
| massOrder of hundreds of thousands to millions of unpatched legacy Windows systems (Windows install base exceeds 1 billion devices) |
Full article309 words · extracted from securelist.com · click to collapse
As we continue to investigate the Duqu targeted attack, there is new information that suggests the malware was created to spy on Iran’s nuclear program.
Some background and facts:
Back in April this year, Iran announced it was victim to a cyber-attack with a virus called “Stars.” This article offers some additional details on that attack.
We can now confirm that some of the targets of Duqu were hit on April 21, using the same method involving CVE-2011-3402, a kernel level exploit in win32k.sys via embedded True Type Font (TTF) file.
According to analysis by IrCERT (Iran’s Computer Emergency Response Team) Duqu is an upgraded version of “Stars”:

If we are to believe these reports, then it means that Duqu was created in order to spy on Iran’s nuclear program.
Just yesterday (November 4), the United Nations announced it was in possession of plans from Iran to make computer models of a nuclear warheads.
“The annex will also say that more than 10 nations have supplied intelligence suggesting Iran is secretly developing components of a nuclear arms program – among them an implosion-type.”
It would not be surprising that Stars and Duqu were used to collect such information.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/duqu-first-spotted-as-stars-malware-in-iran/31632/